mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-09 10:21:03 +00:00
fix(mesh): address Codex audit findings on F-1 PR (#1158)
- docs(sencho-mesh): split subnet_overlap troubleshooting into env-set vs env-unset paths; rewrite the "Customising the mesh subnet" intro to describe the candidate list and the adopt-existing behavior. - backend(MeshService): preserve idempotent 409 handling in the explicit-env path. On createNetwork 409 (TOCTOU race against another process), re-inspect and treat the race-winner as success when its subnet matches the operator's request; subnet_mismatch otherwise. - frontend(MeshDataPlaneBanner): trim the card variant to a true one-line strip (headline only, truncate min-w-0). Full recovery hint stays on the Routing tab variant and in docs. - tests(mesh): add five cases covering the previously untested branches — candidate-loop non-overlap bail, adopt-existing with unparseable subnet, explicit-env generic createNetwork failure, TOCTOU 409 race-winner match, TOCTOU 409 race-winner mismatch. Architecture map (gitignored per Directive 11) updated locally with the new useMeshDataPlane hook node and the mesh.dashboardBanner flow so the local interactive viewer stays accurate.
This commit is contained in:
@@ -662,13 +662,43 @@ export class MeshService extends EventEmitter implements MeshForwarderHost {
|
||||
try {
|
||||
await this.createMeshNetwork(envSubnet);
|
||||
} catch (err) {
|
||||
this.recordSetupFailure(
|
||||
this.classifyMeshNetworkError(err),
|
||||
err,
|
||||
'error',
|
||||
envSubnet,
|
||||
);
|
||||
return;
|
||||
// TOCTOU: another process may have created `sencho_mesh`
|
||||
// between our inspect (returned null) and our create
|
||||
// (rejected with 409). Re-inspect; if the existing
|
||||
// subnet matches what the operator requested, treat
|
||||
// this as idempotent success (matches the prior
|
||||
// ensureMeshNetwork 409-then-inspect behavior). Any
|
||||
// other error or a mismatch reverts to the typed
|
||||
// failure path.
|
||||
const dockerErr = err as { statusCode?: number };
|
||||
if (dockerErr?.statusCode === 409) {
|
||||
const raceWinner = await this.inspectExistingMeshSubnet().catch(() => null);
|
||||
if (raceWinner === envSubnet) {
|
||||
// Adopt the race-winner's network; proceed to attach.
|
||||
} else if (raceWinner) {
|
||||
this.recordSetupFailure(
|
||||
'subnet_mismatch',
|
||||
new Error(
|
||||
`${SENCHO_MESH_NETWORK} exists with subnet ${raceWinner}, ` +
|
||||
`expected ${envSubnet}. Remove the network or set SENCHO_MESH_SUBNET to match.`,
|
||||
),
|
||||
'error',
|
||||
envSubnet,
|
||||
);
|
||||
return;
|
||||
} else {
|
||||
this.recordSetupFailure('attach_failed', err, 'error', envSubnet);
|
||||
return;
|
||||
}
|
||||
} else {
|
||||
this.recordSetupFailure(
|
||||
this.classifyMeshNetworkError(err),
|
||||
err,
|
||||
'error',
|
||||
envSubnet,
|
||||
);
|
||||
return;
|
||||
}
|
||||
}
|
||||
}
|
||||
} else if (existingSubnet) {
|
||||
|
||||
Reference in New Issue
Block a user